62,572 Emails and Password Hashes From the AtletasNow Breach Just Surfaced
HEROIC analysts identified the AtletasNow breach while scanning exposed database repositories in December 2021. The incident affected 62,572 users of this Brazilian sports influencer platform, with the leaked dataset containing a damaging mix of personal and authentication data. The records recieved from the exposure included full names, email addresses, phone numbers, birthdays, genders, and password hashes, giving attackers a comprehensive profile of each affected user.
Why Hashed Passwords Combined With Personal Data Create Serious Risk
Password hashes are not plaintext, but they are not safe either. Attackers with access to hash values can run them through cracking tools and rainbow table lookups, particularly when the hashing algorithm is weak or unsalted. Combined with real names, phone numbers, and birthdays from the same breach, cracked credentials become far more dangerous. Attackers can use this data to bypass security questions, impersonate users, or conduct highly targeted phishing. The combination of PII and password hashes is partcularly favored in credential stuffing operations.
What Was Exposed in the AtletasNow Breach
- Email Address
- Phone Number
- Password Hash
- First Name
- Last Name
- Birthday
- Gender
Why This Breach Puts AtletasNow Users at Ongoing Risk
Breaches involving full names, birthdays, and phone numbers enable identity theft that extends well beyond password reuse. Victims face account takeover on any platform where the same email was registered, SIM swapping attacks using phone numbers, and financial fraud enabled by the combination of personal identifiers. Even users who have since changed their passwords remain at risk because their PII does not change. Attackers who occured access to this data can use it for months or years after the initial breach.
How Database Breaches Work
A database breach occurs when an unauthorized party extracts records from a backend data store, typically through SQL injection, misconfigured access controls, or stolen admin credentials. Once a database is accessed, all tables can be exported silently and quickly. The attacker then sells or publishes the data on dark web forums, where it is aggregated into larger credential collections used in automated attacks against major platforms.
Check If Your Data Was Exposed
HEROIC's free breach scanner searches more than 400 billion records, including data from the AtletasNow breach, to tell you immediately whether your email address has been compromised. Scan your email for free at HEROIC and find out if your information is already in the hands of attackers.
Breach Breakdown
62,572 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds